CVE-2026-0636
published 2026-04-15CVE-2026-0636: Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all…
PriorityP338medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.53%
42.8th percentile
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).
This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| candlepinproject | candlepin | — | — |
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| jenkins | jenkins | — | — |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.74 < 1.80.2 | 1.80.2 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.81 < 1.81.1 | 1.81.1 |
| legion_of_the_bouncy_castle_inc | bc-java | >= 1.82 < 1.84 | 1.84 |
| ocp-tools-4 | jenkins-rhel8 | — | — |
| ocp-tools-4 | jenkins-rhel9 | — | — |
| pki-core_10.6 | resteasy | — | — |
| pki-deps_10.6 | resteasy | — | — |
| redhat | resteasy | — | — |
| rhoai | odh-modelmesh-rhel8 | — | — |
| rhoai | odh-modelmesh-rhel9 | — | — |
| satellite_el8 | candlepin | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:X/RE:M/U:Amber
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Bouncy Castle has an LDAP injection
ghsa·2026-04-17
CVE-2026-0636 [MEDIUM] CWE-90 Bouncy Castle has an LDAP injection
Bouncy Castle has an LDAP injection
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.84.
VulDB
Legion of the Bouncy Castle BC-JAVA up to 1.83 LDAPStoreHelper.java ldap injection
vuldb·2026-04-15·CVSS 5.5
CVE-2026-0636 [MEDIUM] Legion of the Bouncy Castle BC-JAVA up to 1.83 LDAPStoreHelper.java ldap injection
A vulnerability was found in Legion of the Bouncy Castle BC-JAVA up to 1.83 and classified as critical. This vulnerability affects unknown code of the file LDAPStoreHelper.java. The manipulation results in ldap injection.
This vulnerability is known as CVE-2026-0636. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
Red Hat
bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
vendor_redhat·2026-04-15·CVSS 5.5
CVE-2026-0636 [MEDIUM] CWE-90 bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
A flaw was found in Legion of the Bouncy Castle Inc. BC-JAVA bcprov. The `LDAPStoreHelper` implementation fails to properly neutralize special elements in user-supplied input before incorporating them into LDAP queries. This allows a remote attacker to execute an LDAP injection attack by supplying crafted input, potentially leading to disclosure of sensitive information or the manipulation of directory search queries.
Statement: To exploit this issue, an attacker needs to submit crafted input to an application using the `LDAPStoreHelper` implementation for directory queries. An attack typically requires the application to pass the malicious input directly into a search filter, allowing the attacker to modify the
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-0636 voms-api-java: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 voms-api-java: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
CVE-2026-0636 voms-api-java: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 voms-api-java: LDAP injection vulnerability in LDAPStoreHelper.java [epel-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 voms-api-java: LDAP injection vulnerability in LDAPStoreHelper.java [epel-all]
CVE-2026-0636 voms-api-java: LDAP injection vulnerability in LDAPStoreHelper.java [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 pdftk-java: LDAP injection vulnerability in LDAPStoreHelper.java [epel-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 pdftk-java: LDAP injection vulnerability in LDAPStoreHelper.java [epel-all]
CVE-2026-0636 pdftk-java: LDAP injection vulnerability in LDAPStoreHelper.java [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 apache-commons-vfs: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 apache-commons-vfs: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
CVE-2026-0636 apache-commons-vfs: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 pdfbox: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 pdfbox: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
CVE-2026-0636 pdfbox: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 jglobus: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 jglobus: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
CVE-2026-0636 jglobus: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 pdftk-java: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 pdftk-java: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
CVE-2026-0636 pdftk-java: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 canl-java: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 canl-java: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
CVE-2026-0636 canl-java: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 byte-buddy: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 byte-buddy: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
CVE-2026-0636 byte-buddy: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 resteasy: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 resteasy: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
CVE-2026-0636 resteasy: LDAP injection vulnerability in LDAPStoreHelper.java [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 canl-java: LDAP injection vulnerability in LDAPStoreHelper.java [epel-all]
bugzilla·2026-04-28·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 canl-java: LDAP injection vulnerability in LDAPStoreHelper.java [epel-all]
CVE-2026-0636 canl-java: LDAP injection vulnerability in LDAPStoreHelper.java [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0636 bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
bugzilla·2026-04-15·CVSS 5.5
CVE-2026-0636 [MEDIUM] CVE-2026-0636 bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
CVE-2026-0636 bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper.
This issue affects BC-JAVA: from 1.74 before 1.84.
https://github.com/bcgit/bc-java/commit/d20cdb8430e09224114fec0179a71859929fcbdehttps://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%900636https://access.redhat.com/errata/RHSA-2026:11720https://access.redhat.com/errata/RHSA-2026:11721https://access.redhat.com/errata/RHSA-2026:13631https://access.redhat.com/errata/RHSA-2026:14272https://access.redhat.com/errata/RHSA-2026:14276https://access.redhat.com/errata/RHSA-2026:17668https://access.redhat.com/errata/RHSA-2026:18054https://access.redhat.com/errata/RHSA-2026:18055https://access.redhat.com/errata/RHSA-2026:18059https://access.redhat.com/errata/RHSA-2026:21772https://access.redhat.com/errata/RHSA-2026:53644https://access.redhat.com/errata/RHSA-2026:53806https://access.redhat.com/errata/RHSA-2026:60239https://access.redhat.com/errata/RHSA-2026:60246https://access.redhat.com/errata/RHSA-2026:60247https://access.redhat.com/errata/RHSA-2026:60248https://access.redhat.com/errata/RHSA-2026:60249https://access.redhat.com/errata/RHSA-2026:60250https://access.redhat.com/errata/RHSA-2026:60251https://access.redhat.com/errata/RHSA-2026:60252https://access.redhat.com/errata/RHSA-2026:60254https://access.redhat.com/errata/RHSA-2026:60256https://access.redhat.com/errata/RHSA-2026:60259https://access.redhat.com/security/cve/CVE-2026-0636https://bugzilla.redhat.com/show_bug.cgi?id=2458641https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0636.json
2026-04-15
Published